Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ransomware Group Rapidly Disables Security and Encrypts Networks

Ransomware Group Rapidly Disables Security and Encrypts Networks

Posted on September 3, 2026 By CWS

The Gentlemen ransomware group has been observed executing full network encryption with alarming speed, disabling critical security measures within a 24-hour timeframe. The group employs a ransomware-as-a-service model, allowing affiliates to attack accessible targets. Their method includes a double-extortion technique, where data is first stolen and then encrypted, creating both operational and privacy threats for victims.

Understanding the Ransomware Tactics

Research by Sophos on 15 incidents attributed to this group, also known as GOLD SHERWOOD, reveals a repetitive strategy. The group often gains initial access through exposed firewall management interfaces, unpatched systems, or stolen VPN credentials. A particular vulnerability in Fortinet SSL VPNs, when not secured with multi-factor authentication, provides a gateway for these attackers, highlighting the need for robust infrastructure security.

Once inside the network, the attackers utilize legitimate domain credentials and Remote Desktop Protocol to navigate systems. They strategically place their toolkit in trusted Windows locations to avoid detection, mapping data stores and backup systems before launching the ransomware attack. Administrative controls are manipulated, including changing passwords and enabling remote access, often by creating new firewall rules to maintain access even if the initial VPN session is lost.

Disabling Security Measures

The Gentlemen group meticulously removes barriers to encryption by employing both custom and publicly available tools to disable antivirus and endpoint detection systems. They weaken Windows Defender by altering settings and adding scan exclusions, following a broader trend among ransomware operators to neutralize security and backup software before spreading across a network.

In addition to disabling security, they target backup services, often just before initiating encryption, to hinder recovery efforts. In some cases, they erase event logs, further complicating incident response efforts. These actions underscore the importance of maintaining independent backup controls and regularly testing recovery plans to mitigate the impact of such attacks.

Implications and Preventive Measures

The rapid progression from network access to ransomware deployment underscores the crucial need for timely detection and prevention measures. Organizations should prioritize patching internet-facing firewalls and VPN appliances, enforcing multi-factor authentication for remote access, and restricting RDP exposure. Monitoring for unusual activity and reviewing new privileged accounts can aid in early detection of potential threats.

Sophos’ report emphasizes the importance of alerting on atypical activities, such as the use of unfamiliar data-transfer utilities and the modification of Windows Defender settings. By maintaining vigilance and updating security protocols, organizations can reduce the risk of falling victim to such swift and damaging ransomware attacks.

In conclusion, the evolving tactics of ransomware groups like The Gentlemen highlight the ongoing challenges in securing network infrastructures. As cyber threats continue to advance, staying informed and implementing comprehensive security measures is essential for protecting valuable data and maintaining operational continuity.

Cyber Security News Tags:Backup, cyber attack, Cybersecurity, data breach, EDR, Encryption, Fortinet, IT security, Malware, network encryption, network security, Phishing, Ransomware, Sophos, VPN

Post navigation

Previous Post: Pegasus Zero-Click Spyware Targeted Serbian Activists
Next Post: Massive Driver License Data Breach on Dark Web

Related Posts

Microsoft Confirms Recent Updates Cause Login Issues on Windows 11 24H2, 25H2, and Windows Server 2025 Microsoft Confirms Recent Updates Cause Login Issues on Windows 11 24H2, 25H2, and Windows Server 2025 Cyber Security News
Microsoft 365 Under Attack: 81 Million Login Attempts Recorded Microsoft 365 Under Attack: 81 Million Login Attempts Recorded Cyber Security News
Pig-Butchering Scams Operators Scaled Their Operations with The Support of AI-Assistants Pig-Butchering Scams Operators Scaled Their Operations with The Support of AI-Assistants Cyber Security News
SideWinder Targets Government Emails with Fake PDF Viewer SideWinder Targets Government Emails with Fake PDF Viewer Cyber Security News
ConnectWise to Rotate Code Signing Certificates for ScreenConnect, Automate and RMM ConnectWise to Rotate Code Signing Certificates for ScreenConnect, Automate and RMM Cyber Security News
New Microsoft 365 Admin Feature Let Admins Control Link Creation Policies New Microsoft 365 Admin Feature Let Admins Control Link Creation Policies Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Botnet Disruption Successes and DDoS Adaptation
  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Botnet Disruption Successes and DDoS Adaptation
  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark